Configuring MACsec Integrity and Encryption

To ensure point-to-point integrity, MACsec computes an Integrity Check Value (ICV) on the entire Ethernet frame using the designated cipher suite. The designated cipher suite is also used for encryption.

MACsec adds the ICV to the frame before transmission. The receiving device recalculates the ICV and checks it against the computed value that has been added to the frame. Because the ICV is computed on the entire Ethernet frame, any modifications to the frame can be easily recognized.

By default, both encryption and integrity protection are enabled.

MACsec encrypts traffic between devices at the MAC layer and decrypts frames within participating networked devices. MACsec uses the Galois/Counter Mode Advanced Encryption Standard 128 or 256 (GCM-AES-128 or GCM-AES 256) cipher suite to encrypt data and to compute the ICV for each transmitted and received MACsec frame.

MACsec also encrypts the VLAN tag and the original Ethertype field in the Layer 2 header of the secured data. When initial bytes in a secure data packet must be transparent, a confidentiality offset of 30 or 50 bytes can be applied.

Note: Refer to Configuring MACsec for an overview of enabling and configuring MACsec features.

  1. At the dot1x-mka group configuration level, enter the macsec cipher-suite command with one of the available options:
    • gcm-aes-128: Enables encryption and integrity checking using the GCM-AES-128 cipher suite.
    • gcm-aes-128 integrity-only: Enables integrity checking without encryption.
    • gcm-aes-256: Enables encryption and integrity checking using the GCM-AES-256 cipher suite.
    • gcm-aes-256 integrity-only: Enables integrity checking without encryption.

    In the following example, MACsec 128-bit encryption has been configured as a group test1 setting. By default, the ICV integrity check is also enabled, no matter which cipher suite you use.

    device# configure terminal
    device(config)# dot1x-mka  
    device(config-dot1x-mka)# mka-cfg-group test1 
    device(config-dot1x-mka-group-test1)# macsec cipher-suite gcm-aes-128 
    

    In the following example, MACsec has been configured for integrity protection only, without encryption.

    device# configure terminal
    device(config)# dot1x-mka  
    device(config-dot1x-mka)# mka-cfg-group test1
    device(config-dot1x-mka-group-test1)# macsec cipher-suite gcm-aes-128 integrity-only
    
    Note: The no macsec cipher-suite command disables both encryption and integrity checking.

  2. Enter the macsec confidentiality-offset command if an encryption offset is required:
    • 30: Encryption begins at byte 31 of the data packet.
    • 50: Encryption begins at byte 51 of the data packet.
    Note: The default offset for MACsec encryption is zero bytes. Use the no macsec confidentiality-offset command to return the offset to zero bytes.

    In the following example, the encryption offset is defined as 30 bytes. The first 30 bytes of each data packet carried within the MACsec frame are transmitted without encryption.

    
    device# configure terminal
    device(config)# dot1x-mka  
    device(config-dot1x-mka)# mka-cfg-group test1
    device(config-dot1x-mka-group-test1)# macsec confidentiality-offset 30